Inconsistent interpretation of HTTP requests in Apache Tomcat - CVE-2021-33037

 

Inconsistent interpretation of HTTP requests in Apache Tomcat - CVE-2021-33037

Published: July 29, 2021


Vulnerability identifier: #VU55423
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33037
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to preform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP requests, related to processing of transfer encoding headers.  A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

Apache Tomcat
JBoss Web Server
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Web Scripting
Ubuntu
openEuler
BIG-IP
SAN Volume Controller and Storwize Family
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Healthcare Translational Research
Oracle Communications Pricing Design Center
Instantis EnterpriseTrack
Traffix SDC
IBM App Connect Professional
Oracle Secure Global Desktop
Oracle Utilities Testing Accelerator
Oracle Managed File Transfer
MySQL Enterprise Monitor
tomcat9 (Debian package)
Tomcat
javapackages-tools
tomcat
tomcat-help
tomcat-jsvc
libtomcat9-embed-java (Ubuntu package)
tomcat9-common (Ubuntu package)
tomcat9 (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat-admin-webapps
tomcat-docs-webapp
tomcat-el-3_0-api
tomcat-javadoc
tomcat-jsp-2_3-api
tomcat-lib
tomcat-servlet-4_0-api
tomcat-webapps
tomcat9
Oracle Agile PLM Framework
IBM Engineering Requirements Management DOORS Next
Oracle Graph Server and Client
EMC NetWorker Server
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
IBM Spectrum Virtualize for Public Cloud
IBM SAN Volume Controller
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V5100
IBM FlashSystem V9000
IBM FlashSystem 9100 Family
IBM FlashSystem 9200
IBM FlashSystem 7200
IBM FlashSystem 5200
IBM FlashSystem 5000
IBM Spectrum Virtualize Software

How to mitigate CVE-2021-33037

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.68, 9.0.48, 10.0.7
JBoss Web Server - update to 5.6.0
MySQL Enterprise Monitor - update to 8.0.27
tomcat9 (Debian package) - update to 9.0.31-1~deb10u5
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Oracle Graph Server and Client - update to 21.4
Tomcat - update to D.9.0.87.01
javapackages-tools - update to 2.0.1-13.1
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
SAN Volume Controller and Storwize Family - addressed in versions 8.4.0.5, 8.4.2.0
IBM Spectrum Virtualize for Public Cloud - update to 8.4.2.0
IBM SAN Volume Controller - update to 8.4.2.0
IBM Storwize V7000 - update to 8.4.2.0
IBM Storwize V5000 - update to 8.4.2.0
IBM Storwize V5100 - update to 8.4.2.0
IBM FlashSystem V9000 - update to 8.4.2.0
IBM FlashSystem 9100 Family - update to 8.4.2.0
IBM FlashSystem 9200 - update to 8.4.2.0
IBM FlashSystem 7200 - update to 8.4.2.0
IBM FlashSystem 5200 - update to 8.4.2.0
IBM FlashSystem 5000 - update to 8.4.2.0
IBM Spectrum Virtualize Software - update to 8.4.2.0
tomcat - update to 9.0.10-19
tomcat-help - update to 9.0.10-19
tomcat-jsvc - update to 9.0.10-19
libtomcat9-embed-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9-common (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9 (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-admin-webapps - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-docs-webapp - update to 9.0.36-3.71.1
tomcat-el-3_0-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-javadoc - update to 9.0.36-3.71.1
tomcat-jsp-2_3-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-lib - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-webapps - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat9 - update to 9.0.64-1
EMC NetWorker Server - addressed in versions 19.5.0.4, 19.6.0

External References

Related Security Bulletins